The repository has tests, a matching README, and recent commits from two contributors. One contributor made nearly all recent commits, while no security policy or scanning is present.
61%
Total Score
75
88
50
The package defines a post-root-package-install script, adding install-time behavior that consumers must trust beyond ordinary dependency loading.
This is a brand-new package with only one release and no established release interval, so its maintenance record and maturity are unproven.
Recent work is highly concentrated: one contributor made 15 of 16 commits, leaving limited demonstrated handoff capacity despite a second contributor being active.
Composer is used for builds, but no security-scanning tool was detected, leaving a transparency and maintenance-control gap.
The repository has no security policy, so users lack documented guidance for reporting and handling vulnerabilities.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
firebase/php-jwt Version ^7.1 | — | — |
psr/http-message Version ^2.0 | — | — |
vlucas/phpdotenv Version ^5.2 | — | — |
doctrine/inflector Version ^2.0 | — | — |
phpmailer/phpmailer Version ^7.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.